Back to ThreatBox
ThreatBox · Threat Actor Attribution

APT28

a.k.a. Fancy Bear, Sofacy, STRONTIUM, Forest Blizzard, Pawn Storm, GRU Unit 26165
Espionage (state-sponsored, military intelligence) Russia (GRU Military Intelligence) First seen 2004

APT28 is Russia's GRU (military intelligence) cyber unit, tasked with strategic espionage and information operations. Best known for the 2016 DNC hack and the TV5Monde attack (2015). Continues to run credential-phishing at scale against military/government targets, especially in Ukraine post-2022. Uses custom malware (X-Agent, Zebrocy, HeadLace) and heavy exploitation of Outlook/Roundcube CVEs.

Targeted sectors
GovernmentMilitaryDefense contractorsMediaPolitical organisations
Targeted regions
NATO countriesUkraineGeorgia

Known TTPs (4)

Click any technique to open the MITRE ATT&CK reference.

Attack Timeline

  1. 2015-04
    TV5Monde broadcast disruption
  2. 2016-07
    DNC email leak (US election interference)
  3. 2018-07
    Mueller indictment of 12 GRU officers
  4. 2023-03
    CVE-2023-23397 Outlook zero-day mass-exploitation (Ukraine targets)

References

End of dossier · APT28
Back to ThreatBox

Made with Emergent